aicoin-market

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The file lib/defaults.json contains hardcoded accessKeyId and accessSecret values. These are functional API keys for the service's free tier.
  • [COMMAND_EXECUTION]: The script scripts/coin.mjs includes an update_key function that uses writeFileSync to modify local .env configuration files on the user's system.
  • [PROMPT_INJECTION]: The skill ingests external content from news flashes and Twitter feeds in scripts/news.mjs and scripts/twitter.mjs, which constitutes a surface for indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 02:07 PM